Login
Download
Skill UI
Browse and discover
15857+
curated skills
All
Development
Artificial Intelligence
Design & Creative
Product & Business
Data Science
Marketing
Soft Skills
Productivity
Engineering
Languages
Search
PKINIT
, found
5
results
Default
Newest
Most Downloaded
Exploiting AD CS For Privilege Escalation
exploiting-active-directory-certificate-services-esc1
mukul975/Anthropic-Cybersecurity-Skills
115
This guide details the exploitation of the Active Directory Certificate Services (AD CS) ESC1 vulnerability. By leveraging misconfigurations, an attacker can request certificates impersonating high-privileged users (e.g., Domain Admins). The workflow covers AD enumeration, forging certificates with arbitrary Subject Alternative Names (SANs), authenticating via PKINIT, and ultimately escalating domain privileges using tools like mimikatz. Essential for authorized red team and penetration testing.
View Details
Abusing Shadow Credentials For AD Takeover
abusing-shadow-credentials-for-privesc
mukul975/Anthropic-Cybersecurity-Skills
76
This technique abuses the Active Directory's `msDS-KeyCredentialLink` attribute to inject attacker-controlled public keys (Shadow Credentials). After gaining write access (e.g., via BloodHound), the attacker uses tools like pyWhisker or Certipy to append their key. They then authenticate via PKINIT to recover the target's NT hash, achieving complete account takeover without the disruptive step of a password reset. Ideal for stealthy red-teaming engagements.
View Details
Exploiting AD CS Certificates with Certipy
exploiting-adcs-with-certipy
mukul975/Anthropic-Cybersecurity-Skills
186
A comprehensive red-teaming technique for Active Directory Certificate Services (AD CS). This skill utilizes the Certipy toolkit to enumerate and exploit various Certificate Service Configuration (ESC1-ESC16) misconfigurations over LDAP/RPC. It enables attackers to forge privileged certificates and perform PKINIT authentication, escalating a low-level domain foothold to Domain Admin or Domain Controller access during authorized penetration tests.
View Details
Relaying NTLM to AD CS Web Enrollment
relaying-ntlm-for-adcs-esc8
mukul975/Anthropic-Cybersecurity-Skills
248
This technique exploits vulnerable Active Directory Certificate Services (AD CS) HTTP web-enrollment endpoints (ESC8) that lack Extended Protection for Authentication (EPA). By coercing a Domain Controller (DC) to authenticate and relaying the captured NTLM credentials, an attacker can obtain a DC machine certificate. This certificate is then used via PKINIT to request a TGT, recover the DC's NT hash, and ultimately achieve full domain compromise via DCSync. Essential for advanced AD red-teaming simulations.
View Details
Analyzing AD Certificate Abuse
competition-ad-certificate-abuse
zhaoxuya520/reverse-skill
137
This specialized skill guides users through analyzing complex Active Directory Certificate Services (AD CS) abuse scenarios. It is essential for proving how a weakness in a template, CA policy, or issuance right can lead to unauthorized privilege acceptance (e.g., via PKINIT, Schannel). The workflow focuses on mapping the entire certificate issuance chain to the resulting accepted service path.
View Details
1
Language
简体中文
English